Linux Ransomware Pay2Key Attacking Organizations Ervers, Virtualization Hosts, and Cloud Workloads
ID: 6e37edd2-d63f-58b1-a1b9-6f78f75c3f0b
STIX ID: report--6e37edd2-d63f-58b1-a1b9-6f78f75c3f0b
Feed Name: cybersecurityNews.com
This report describes Pay2Key.I2, a Linux-targeting variant of the Pay2Key ransomware attributed to Iranian threat actors that was first observed in late August 2025; the sample is configuration-driven, requires root privileges, disables SELinux and AppArmor, installs cron persistence, enumerates mounted filesystems to selectively encrypt targets using ChaCha20 with per-file keys and obfuscated metadata, and is designed to impact servers, virtualization hosts, and cloud workloads.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
